{% if COMMON_ENABLE_BASIC_AUTH %}
     satisfy any;

     allow 127.0.0.1;
     allow 10.0.0.0/8;
     allow 192.168.0.0/16;
     allow 172.16.0.0/12;
     deny all;

     auth_basic            "Restricted";
     auth_basic_user_file  {{ nginx_htpasswd_file }};

     index index.html
     proxy_set_header X-Forwarded-Proto https;
{% endif %}
